InfraNestInfraNest

Automation

Dynamic DNS for records and firewalls

Point your router, office or home lab at one update URL and let every dependent DNS record and cloud firewall rule follow your changing IP automatically. One source can drive many targets, across providers, for IPv4 and IPv6 alike.

Free plan · No credit card · Works with any dyndns2 router or client

Dynamic IP sources3 sources · 11 targets tracked
HostCurrent IPUpdated
home-lab.example.com82.12.44.192 min ago
office-fritzbox.example.com145.94.8.20338 min ago
remote-nas.example.com2a02:8109:9c0:…:af211 hr ago
backup-line.example.com91.66.20.7stale · 3 days

Every dependent record and firewall rule follows the current IP.

Works with your DNS providers

CloudflareAWS Route 53IONOSTransIPHetznerNamecheapSee all 42 →

DNS records that follow a changing address

Tick “Track with a Dynamic IP” on any A or AAAA record and it points at the current address for that source — no cron jobs, no scripts. One source can drive as many records as you like, at whichever provider hosts each zone.

  • A and AAAA records tracked, for IPv4 and IPv6 alike
  • One source drives many records, across providers
  • The moment your IP moves, every record moves with it
Records tracking home-lab.example.com82.12.44.19 · updated 2 min ago
A · vpn.example.comCloudflare · in sync
A · git.example.comHetzner · in sync
AAAA · nas.example.comIONOS · in sync
A · cam.example.comTransIP · updating

Four records, three providers, one changing address.

Firewall rules that follow the same address

The same source can pin cloud firewall allow-rules, so an SSH or admin port stays open to you and no one else. When your IP changes the allowlist is rewritten in step with DNS, so remote access never locks you out and never goes stale.

  • Inbound allow-rules pinned to your current address, not the whole internet
  • DNS and firewalls updated together, never one without the other
  • No more re-whitelisting your office by hand every time it changes
Firewalls following home-lab.example.com3 rules rewritten · 82.12.44.19
SSHweb-01 · port 22 allow updated to 82.12.44.19/32Updated
ADMINdb-01 · port 5432 allow updated to 82.12.44.19/32Updated
RDPwin-app · port 3389 still on old 84.3.11.9Retrying →

A tiny updater pushes the current IP

Create a source and you get an update URL and token that speak the dyndns2 protocol — the same one ddclient and most routers already talk. Point your FRITZ!Box, ddclient or a one-line cron at it and InfraNest fans the address out to every target from there.

  • Works with most routers and ddclient out of the box
  • A one-line cron or a single API call is enough
  • Failed pushes retry, and you can be alerted on every change
IP change propagating · home-lab.example.com
Router reports new IP 82.12.44.190s
Source updated, 7 targets queued1s
DNS A/AAAA records rewritten4s
Firewall allow-rules rewritten9s

From router to DNS and firewalls in under ten seconds.

Everything else it handles

The parts that are only interesting when you need them.

IPv4 and IPv6 together

Track an A record, an AAAA record, or both from one source — dual-stack connections stay correct on either protocol.

Many targets per source

One update drives every dependent record and firewall rule at once, however many there are and wherever they live.

Retries and change alerts

A failed push retries with backoff, and you can be notified whenever your address actually changes — or when an update fails.

dyndns2 compatibility

The standard update protocol, so ddclient, most routers and existing scripts work without custom client software.

Router presets

Copy-paste setup for FRITZ!Box, OPNsense, pfSense and UniFi, so a home or office gateway is pointed in minutes.

Stale-source detection

If a source stops reporting, InfraNest flags it before a silent failure leaves your records pointing at the wrong place.

Per-target sync status

See at a glance which records and rules are in sync, updating or failing for every source.

Full audit trail

Every address change and the updates it triggered are logged, so you can see exactly what moved and when.

Point one source at InfraNest in about two minutes

Create a Dynamic IP source, copy the update URL into your router, and watch a record follow it. Nothing else changes.

Classic DDNS by hand vs InfraNest

The difference between updating one name and keeping everything in sync.

By hand

  • A DDNS service that updates one DNS name and nothing else
  • Firewall allow-rules that quietly go stale and lock you out
  • Custom client software installed on every device
  • A failed update that silently loses your new address

With InfraNest

  • DNS records and firewall rules updated in the same step
  • Many targets per source, across every provider you use
  • Any dyndns2 router or client works with no extra software
  • IPv4 and IPv6, with retries and an alert on every change

Pairs well with

Frequently asked

What is dynamic DNS?

Dynamic DNS keeps DNS records pointed at a connection whose public IP changes — like a home, office or lab. InfraNest goes further than classic DDNS: one address change updates your DNS records and your cloud firewall allow-rules at the same time, across providers.

Which routers and clients work?

Anything that speaks the dyndns2 protocol, which covers ddclient, FRITZ!Box, OPNsense, pfSense, UniFi and most consumer routers. You can also update from a one-line cron or a single API call — no custom software required.

Does it support IPv6?

Yes. A source can track an A record, an AAAA record, or both, so dual-stack connections stay correct on either protocol as the address changes.

Can one source update more than one thing?

Yes — that is the point. A single source can drive any number of DNS records and firewall allow-rules at once, at whichever providers host them, all from one update.

What happens if an update fails?

InfraNest retries with backoff and shows the target as failing rather than silently losing your address. You can be alerted whenever your IP changes or when an update does not go through.

One IP, everything in sync

Point one source at InfraNest and watch your records and firewalls follow it.

Start for free